Vulnerabilities > CVE-2003-1516 - Cross-Site Applet Sandbox Security Model Violation vulnerability in SUN Java Plug-In 1.4.201

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
sun
exploit available

Summary

The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.

Vulnerable Configurations

Part Description Count
Application
Sun
1

Exploit-Db

descriptionSun Java Plug-In 1.4.2 _01 Cross-Site Applet Sandbox Security Model Violation Vulnerability. CVE-2003-1516. Remote exploit for windows platform
idEDB-ID:23265
last seen2016-02-02
modified2003-10-20
published2003-10-20
reporterMarc Schoenefeld
sourcehttps://www.exploit-db.com/download/23265/
titleSun Java Plugin 1.4.2 _01 - Cross-Site Applet Sandbox Security Model Violation Vulnerability